Ylefebvre
Ylefebvre Link Library: vulnerabilidades y CVE
Ylefebvre Link Library tiene 24 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses9
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78397 | Media (4) | 0.16% | — | 25 sept 2026 | The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to… |
| CVE-2026-78394 | Media (4.1) | 0.24% | — | 25 sept 2026 | The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and… |
| CVE-2026-78393 | Media (6.1) | 0.15% | — | 25 sept 2026 | The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site… |
| CVE-2026-18855 | Crítica (9.1) | 1.4% | — | 15 ago 2026 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it… |
| CVE-2026-16535 | Media (6.1) | 0.27% | — | 8 ago 2026 | The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks… |
| CVE-2026-16532 | Crítica (9.1) | 0.46% | — | 3 ago 2026 | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. |
| CVE-2026-18197 | Media (6.4) | 0.28% | — | 29 jul 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4. |
| CVE-2026-40779 | Alta (7.7) | 0.47% | — | 15 jun 2026 | Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions. |
| CVE-2025-68600 | Media (4.9) | 0.14% | — | 24 dic 2025 | Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7. |
| CVE-2025-46237 | Media (5.4) | 0.22% | — | 22 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from n/a through <= 7.8. |
| CVE-2025-2889 | Media (6.4) | 0.25% | — | 5 abr 2025 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output… |
| CVE-2024-13404 | Media (6.1) | 0.29% | — | 21 ene 2025 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping.… |
| CVE-2024-38711 | Media (6.1) | 0.35% | — | 20 jul 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1. |
| CVE-2024-35687 | Media (6.1) | 0.33% | — | 8 jun 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a… |
| CVE-2024-4281 | Media (5.4) | 0.26% | — | 8 may 2024 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output… |
| CVE-2024-2325 | Media (6.1) | 0.41% | — | 9 abr 2024 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping.… |
| CVE-2024-29123 | Media (6.1) | 0.42% | — | 19 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6. |
| CVE-2024-1559 | Media (6.1) | 0.41% | — | 20 feb 2024 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping.… |
| CVE-2024-24875 | Alta (8.8) | 0.21% | — | 12 feb 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13. |
| CVE-2024-24879 | Media (6.1) | 0.38% | — | 8 feb 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13. |
| CVE-2022-4199 | Media (4.8) | 0.47% | — | 16 ene 2023 | The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2021-25093 | Alta (7.5) | 1.2% | — | 1 feb 2022 | The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request |
| CVE-2021-25092 | Media (6.5) | 0.48% | — | 1 feb 2022 | The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack |
| CVE-2021-25091 | Media (6.1) | 0.80% | — | 1 feb 2022 | The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.